HI,
I have a query index=something | timechart latest(fieldA) as datavalues by dataNames.
when i select the time duration Today or Yesterday up to last 30days , it's working fine. If I select the last 3 months, it's displaying the wrong results.
Can you please help me on this?
@skoelpin yes same data same timestamp from last one year onwards
Can you post a screenshot of what you see and explain what you're looking to get?
Are you referring to different time spans as you extend the time period?
Have you confirmed your timestamp is correct from 3 months ago?
timechart has auto spaning depends on the time picker
see here: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/timechart